QID 91845
Date Published: 2021-12-15
QID 91845: Microsoft Windows Codecs Library HEVC Video And Web Media Extensions Remote Code Execution (RCE) Vulnerability for December 2021
A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.
Affected Product:
"HEVC from Device Manufacturer" media codec before version 1.0.42702.0
"WEB from Device Manufacturer" media codec before version 1.0.42192.0
QID detection Logic:
The gets the version of HEVCVideoExtension and WebMediaExtensions by querying wmi class Win32_InstalledStoreProgram.
An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system
Solution
Users are advised to check CVE-2021-41360
CVE-2021-40452
CVE-2021-40453 and
CVE-2021-43214
for more information.
Vendor References
- CVE-2021-40452 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40452 - CVE-2021-40453 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40453 - CVE-2021-41360 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41360 - CVE-2021-43214 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43214
CVEs related to QID 91845
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-40452 |
|
||
| CVE-2021-40453 |
|
||
| CVE-2021-41360 |
|
||
| CVE-2021-43214 |
|